Vulnerability in C-STORE Handler of qrscp Application by Pydicom
CVE-2026-56445

8.8HIGH

Key Information:

Vendor

Pydicom

Vendor
CVE Published:
25 June 2026

What is CVE-2026-56445?

The qrscp application has a vulnerability in its C-STORE handler that permits an attacker to manipulate DICOM datasets. It directly uses data from untrusted sources in the os.path.join() function without proper sanitization, creating the risk of unauthorized file writes to arbitrary system paths. This flaw could be exploited to compromise the integrity of the file system and potentially execute malicious actions.

Affected Version(s)

pynetdicom Library 1.0.0 <= 3.0.4

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Simon Weber and Volker Schönefeld of Machine Spirits UG reported this vulnerability to CISA.
.